Skip to main content
Mallory
🇦🇷 🇧🇷 🇮🇩 🇰🇷 🇺🇸 🇻🇳 AR3 malware familiesExploits CVEs in the wild

Outlaw

Also known asoutlaw

Outlaw is a long-running Linux-focused botnet and hacking group, also referred to in reporting as Shellbot and Dota. Trend Micro first identified the group in 2018. The activity described in the provided content targets Linux and Unix servers, vulnerable servers, and IoT devices, with reported targeting of organizations in the United States and Europe, including possible automotive and finance victims. Observed tradecraft includes SSH and Telnet brute-force attacks using weak credentials, exploitation of CVE-2016-8655 and Dirty COW (CVE-2016-5195), and use of PHP web shells. A recurring and well-documented persistence mechanism is replacement of ~/.ssh/authorized_keys with an attacker-controlled RSA public key carrying the comment string "mdrfckr," often preceded by commands such as chattr -ia .ssh and lockr -ia .ssh to remove file protections. Multiple reports in the content associate this key-write playbook and the authorized_keys artifact with SHA-256 a8460f446be540410004b1a8db4083773fa46f7fe76fa84219c93daa1669f8f2 to Outlaw/Shellbot activity. The group’s post-compromise behavior includes reconnaissance commands such as uname -a or uname -s -v -n -r -m, collection of host intelligence, password changes, and cleanup/removal of competing miners and prior infections. Outlaw deploys Shellbot disguised as rsync for evasion, uses cron jobs and looping scripts for persistence, and has operated large-scale scanning from command-and-control infrastructure. Reporting in the content also describes monetization through cryptojacking, including miner deployment and removal of competing miners, and notes Android TV mining-related APK/ADB artifacts in one campaign. Historical reporting in the content ties Outlaw/Shellbot activity to evolving libssh-based SSH client fingerprints, including older libssh 0.6.x and 0.9.x generations and a 2026 cluster using banner SSH-2.0-libssh_0.11.1 with hassh 03a80b21afa810682a776a7d42e5e6fb. The content emphasizes that more stable identifiers for this actor include the "mdrfckr" key comment, the authorized_keys artifact hash, and the established SSH persistence and recon command sequence. Known aliases: Shellbot, Dota.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Where they're from

Attributed origin per open-source reporting.

  • AR
  • BR
  • ID
  • KR
  • US
  • VN
MITRE ATT&CK

Tradecraft

21 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

11 of 15 tactics33 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
1 technique
T1078
Valid Accounts
TA0002
Execution
2 techniques
T1053
Scheduled Task/Job
T1053.003
Cron
T1059
Command and Scripting Interpreter
T1059.004
Unix Shell
T1059.006
Python
TA0003
Persistence
4 techniques
T1053
Scheduled Task/Job
T1053.003
Cron
T1078
Valid Accounts
T1098×2
Account Manipulation
T1098.004×2
SSH Authorized Keys
T1505
Server Software Component
T1505.003
Web Shell
TA0004
Privilege Escalation
4 techniques
T1053
Scheduled Task/Job
T1053.003
Cron
T1068
Exploitation for Privilege Escalation
T1078
Valid Accounts
T1098×2
Account Manipulation
T1098.004×2
SSH Authorized Keys
TA0005
Stealth
4 techniques
T1027
Obfuscated Files or Information
T1036
Masquerading
T1070×2
Indicator Removal
T1078
Valid Accounts
TA0112
Defense Impairment
1 technique
T1222×2
File and Directory Permissions Modification
TA0006
Credential Access
1 technique
T1110×3
Brute Force
TA0007
Discovery
3 techniques
T1033
System Owner/User Discovery
T1046
Network Service Discovery
T1082
System Information Discovery
TA0008
Lateral Movement
1 technique
T1210
Exploitation of Remote Services
TA0011
Command and Control
3 techniques
T1071
Application Layer Protocol
T1105×2
Ingress Tool Transfer
T1219
Remote Access Tools
TA0040
Impact
1 technique
T1496
Resource Hijacking
IOCS

Observables

15 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

codebyNews
Jun 4, 2026
Поднял SSH-ловушку и поймал живой ботнет

A long-running botnet campaign conducting opportunistic SSH compromise activity worldwide. In the observed activity, infected nodes attempted to replace .ssh directories, add the same attacker-controlled SSH public key with the comment 'mdrfckr' into authorized_keys, and establish persistent backdoor access on newly compromised hosts.

Read more
handlers diary fullNews
May 15, 2026
[Guest Diary] New Malware Libraries means New Signatures

Long-running SSH botnet/crypto-botnet activity using the stable 'mdrfckr' authorized_keys persistence artifact, brute-force SSH logins with a fixed credential dictionary, account hijacking via chpasswd, reconnaissance, and competitor-cleanup commands. The April 2026 observation shows the same campaign updating its SSH client tooling to libssh 0.11.1 while retaining the same persistence key and playbook.

Read more
cloudatg insightsNews
Feb 13, 2026
AI Development & Software Engineering | CloudATG

Linux-focused botnet using SSH brute-force, worm-like propagation, and cryptomining deployment.

Read more
flareio blogNews
Feb 9, 2026
Old-School IRC, New Victims: Inside the Newly Discovered SSHStalker Linux Botnet - Flare | Threat Exposure Management | Unmatched Visibility into Cybercrime

Referenced as a historically documented Linux botnet operation whose playbooks (SSH brute-force, automated staging, IRC coordination, cron persistence) resemble SSHStalker; the content explicitly states there is no direct evidence tying this activity to Outlaw and suggests SSHStalker may be a derivative/copycat/adjacent operator.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping21

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal3

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs2

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables15

Domains, IPs, and hashes tied to this actor, refreshed continuously.